Security protections
Licenses, lookalikes and provenance
License rules, typosquat detection, and signed build provenance.
Licenses
Settings, Licenses tab. What to do about it: off, warn or enforce. Under enforce, a license on the Needs review list is held for review and one on Blocked is held and rejected. For MIT OR GPL-3.0 the most permissive part counts. For AND the strictest part counts.
Lookalike packages
Typosquat checks (warn, block or off) compare new names against popular packages and your own busiest ones, looking for swapped letters, look alike characters like 0 for o, extra words like -js, and scope tricks. Warn prints a TYPOSQUAT notice, block refuses. In whitelist mode an unknown name is already refused by the rules first. The Lookalike packages page lists findings and lets you mark one not a typosquat.
Provenance
For npm and PyPI, ForgeRepo™ verifies Sigstore signed build provenance against the exact file it holds. Results are VERIFIED, PRESENT_UNVERIFIED, MISSING or INVALID, shown on Artifacts. When provenance is INVALID: warn (default) or hold.